Trojan

TrojanDownloader:Win32/Beebone.D removal guide

Malware Removal

The TrojanDownloader:Win32/Beebone.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Beebone.D virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Beebone.D?


File Info:

name: 6238293AE638D214B9DA.mlw
path: /opt/CAPEv2/storage/binaries/2a6499c789a9e6fa4c51a90eee90308c731b191b1032701cecf2cf2c36d6e2e8
crc32: C24267D9
md5: 6238293ae638d214b9da0fafcdcea5eb
sha1: 02cf290321fd016ebc97779c5e095e6411fd2290
sha256: 2a6499c789a9e6fa4c51a90eee90308c731b191b1032701cecf2cf2c36d6e2e8
sha512: 7a8de41693251b5c1762096383f524280bfc893ad3b144fe6c58cdef4ae8d834f6777520c533f3f50cf42b49464b16f6f6598387cca1889f568ca433db1ae384
ssdeep: 768:hoNI1mYXVDlVe5pTSkelXIqWoBP1t2a6aEAE9puSjgHZh:hoNIPePyIqfBP10sZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19713D617E904842BD691CAF21D20D5E9382B3E760690AF073688BF1D2A72B4379F571F
sha3_384: 63c8295dbc51a6324ff076f20ec412115658deaee42237e37264f78974d5f2aac086a70b526480b39b0d60508892340e
ep_bytes: 68b81a4000e8f0ffffff000048000000
timestamp: 2012-03-09 02:08:52

Version Info:

0: [No Data]

TrojanDownloader:Win32/Beebone.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injector.m0xp
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.6238293ae638d214
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.Autorun.pt
ALYacGen:Variant.VBInject.11
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
BitDefenderGen:Variant.VBInject.11
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.321fd0
BaiduWin32.Trojan-Downloader.VB.q
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.VB.PPI
APEXMalicious
ClamAVWin.Dropper.Agent-36790
KasperskyTrojan-Downloader.Win32.VB.haoo
AlibabaTrojanDownloader:Win32/VBDown.756a6956
NANO-AntivirusTrojan.Win32.Drop.cexciu
ViRobotDropper.Injector.45056.A
RisingWorm.VobfusEx!1.99DC (CLASSIC)
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.MulDrop3.41041
ZillyaDropper.Injector.Win32.17987
TrendMicroTROJ_INJECTOR_00002b6.TOMA
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Injector.znz
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen7
VaristW32/VB.EP.gen!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.Injector
KingsoftWin32.HeurC.KVM007.a
MicrosoftTrojanDownloader:Win32/Beebone.D
XcitiumTrojWare.Win32.TrojanDownloader.VB.BWUU@4pctrr
ArcabitTrojan.VBInject.11
SUPERAntiSpywareTrojan.Agent/Gen-TrojanDownloder
ZoneAlarmTrojan-Downloader.Win32.VB.haoo
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Injector.R23238
McAfeeDownloader-FEE!6238293AE638
TACHYONTrojan-Downloader/W32.Agent.45056
DeepInstinctMALICIOUS
VBA32TrojanDropper.Injector
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_INJECTOR_00002b6.TOMA
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!8XhvaFv7SuM
IkarusTrojan-Downloader.VB
MaxSecureTrojan.Malware.3708546.susgen
FortinetW32/VB.PPE!tr
BitDefenderThetaGen:NN.ZevbaF.36792.cmW@amaZERfi
AVGWin32:Downloader-NLH [Trj]
AvastWin32:Downloader-NLH [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove TrojanDownloader:Win32/Beebone.D?

TrojanDownloader:Win32/Beebone.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment